Privacy Policy
Last Updated: July 23, 2026
At StrikeBooks, we are committed to protecting the privacy of freelance professionals in the production industry.
1. Information We Collect
Account Information: Name, email address, and password (or Google sign-in identity if you choose that login method).
Business Identity: Business name, address, phone number, and branding logos.
Professional Data: Client contact details, project names, venue locations you attach to jobs, and rate card configurations.
Financial Data: Invoices generated, income records, expense receipts, mileage logs, and related billing patterns you enter to run the service.
Optional Google / Gmail connection: If you choose to connect Gmail in Settings → Integrations, we receive an OAuth access token from Google (stored by our platform provider, Base44) so StrikeBooks can send invoice emails from your Gmail address when you ask us to. We may also read your Google account email (via Google’s identity/userinfo APIs, not your inbox) solely to confirm the connection and show which address invoices will send from. We do not import, sync, or store your inbox, drafts, contacts list, or other mailbox contents for this feature.
What we do not collect for normal use: StrikeBooks does not ask for Social Security numbers, government-issued ID numbers, or similar highly sensitive identity documents. Subscription card payments are processed by Stripe; StrikeBooks does not store full payment card numbers.
2. How We Use Your Information
StrikeBooks uses your data to generate professional PDF invoices, calculate overtime and premiums, process subscription payments via Stripe, send invoice emails you initiate, and provide customer support.
Invoice email delivery: By default, invoice emails you send through StrikeBooks may be delivered via our transactional email provider (currently Resend) from StrikeBooks’ sending domain. If you connect Gmail and choose to send from your own address, we use the Google Gmail API only to transmit the invoice message and PDF attachment you requested to the recipients you specify.
Shared venue directory: To speed up lookup and keep timezone and per diem data accurate, StrikeBooks maintains a shared catalog of public venue places (name, address, coordinates, timezone, and government per diem rates). When you select a venue from Google Places that isn’t already in that catalog, its public place details may be added so other StrikeBooks users can find the same location. This catalog does not include your jobs, clients, invoices, or job-specific venue notes, and it does not show which user added or used a venue.
2.5 Google Gmail API (Limited Use)
StrikeBooks’ use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Purpose: We request Gmail send permission only to transmit invoice emails and PDF attachments on your behalf when you initiate a send. We use Google’s identity/userinfo APIs (not Gmail mailbox read) to confirm the connected account and show which address invoices will send from. We do not use Gmail data to train generalized AI/ML models, to serve advertisements, or for any purpose unrelated to providing these user-facing features.
Access & storage: OAuth tokens for your Gmail connection are stored by Base44 as part of the App User connector. StrikeBooks server functions use that token only at send time (and for the limited connection-status check described above). We may store delivery metadata on the invoice record you own (for example, that an email was sent via Gmail and a provider message id) so you can see send status in the app.
Human access: StrikeBooks personnel do not read your Gmail mailbox. Access to Gmail-derived tokens or send logs is limited to automated systems and, only when necessary, to diagnosing a send failure you report, under our normal support access controls.
Your control: Connecting Gmail is optional. You may disconnect Gmail at any time in Settings → Integrations, which revokes StrikeBooks’ ability to send from that account via the stored connection. You may also revoke access in your Google Account security settings.
3. Data Security
StrikeBooks is built on Base44, a platform that provides authentication, hosting, and data storage with enterprise-oriented security controls. Base44 publicly states that it is SOC 2 Type II and ISO 27001 certified, encrypts data in transit and at rest, and maintains GDPR-oriented privacy practices. Details of Base44's platform security are available at base44.com/security.
Authentication: Access to your StrikeBooks account requires signing in through Base44's authentication system (email and password and/or Google sign-in). Protected areas of the app are available only to authenticated users.
Account isolation: Your jobs, invoices, clients, expenses, mileage, rate cards, and account settings are protected with row-level access rules so that other StrikeBooks users cannot read or change your private records through the normal application interface. The shared public venue directory described above is an exception: it is readable by other StrikeBooks users as reference data, and does not include your private job, client, or invoice records.
Support access: When needed for customer support or platform operations, limited administrative tools may be used under access controls. Financial and personal business records are not exposed to other customers.
Operational safeguards: Sensitive integration credentials are kept in server-side secret storage rather than in the public app. Public or automated endpoints (such as payment webhooks or optional calendar feeds) use token, signature, or secret-based checks as appropriate. Calendar feed links, if you enable them, should be treated like passwords and can be revoked in Settings. Optional Google connector tokens are likewise stored server-side and are not exposed in the public client.
Data location: By default, Base44 stores application data in the United States. Base44 may use subprocessors to help host and operate the platform; see Base44's security and privacy documentation for current details.
Your responsibilities: Use a strong unique password or Google sign-in, sign out on shared devices, and only share invoice or calendar links with people you intend to grant access. If you connect Gmail, only connect an account you intend StrikeBooks to send invoice email from.
4. Third-Party Services
We do not sell your personal data. We share information with trusted third parties only as needed to operate StrikeBooks: Base44 for hosting, authentication, data storage, and optional third-party OAuth connectors (including Gmail); Stripe for subscription payment processing; Google (Google Places for venue lookups that may populate the shared venue directory described above, and—only if you connect Gmail—Google’s Gmail API to send invoices from your address, plus Google identity/userinfo to confirm the connected account); and email delivery providers such as Resend when invoice email is sent via StrikeBooks’ sending domain or for service communications.
5. Data Retention & Control
You retain full ownership of your business data and may update or delete your profile at any time through application settings. Upon cancellation, we retain data only as required by law or as needed to complete outstanding support or legal obligations. Disconnecting Gmail stops future Gmail sends; invoice records and any send-status metadata already saved on those invoices remain part of your account data until you delete them or close your account under our normal retention practices.
6. Contact Us
For privacy or security questions about StrikeBooks, contact us at:
Email: support@strikebooks.com